If your data is so sensitive that you do not want to store it on a central server then why not consider the PGP approach?
User 2 sends a request to user 1 (who has the data) sending his or her public key and asking for the data encrypted using the public key. User 2 then decrypts the message using his private key and makes his own local copy.
How do you communicate data changes between data holders - a version control problem perhaps?