a) First express them in English as a set of 3 to 5 rules. For example one rule might be "I don't want companies to share my data." If you can't capture all of your privacy preferences in 5 rules, just write down the 5 rules you consider most important.
b) Translate your rules into P3P vocabulary elements (for example, the above rule would translate to "RECIPIENT=ours")
c) Create an APPEL ruleset that represents your set of 3 to 5 privacy preference rules (plus a catch-all rule)